321 points by hn_acker 5 days ago | 202 comments | View on ycombinator
jsrozner 4 days ago |
joshfraser 4 days ago |
It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.
AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.
These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.
The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
curuinor 5 days ago |
O3marchnative 4 days ago |
[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
er4hn 4 days ago |
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
0xmattf 4 days ago |
I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.
I think IDScan should set something up so we can check if our data was compromised, at the least.
nullc 4 days ago |
Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.
(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)
In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
sandeepkd 4 days ago |
Ironically in case of breach they just sell you another of their product where you put your personal information again
robinsoncrusue 4 days ago |
techgnosis 4 days ago |
If we fix that, then having your ID stolen is a much, much smaller problem.
exabrial 5 days ago |
xtiansimon 4 days ago |
Personally, data security is the AI Doom I’m concerned about, not being turned into paperclips.
deepsquirrelnet 4 days ago |
ProllyInfamous 4 days ago |
Also: many US states allow you to use a PO Box on your license (e.g: Calif., Tenn., Texas)
anxman 5 days ago |
ChrisMarshallNY 4 days ago |
I suspect the reason for that (nothing other than a "gut feeling" that I get, seeing the story pushed off the front page so quickly, every time), is that the breach was through a backdoor that was deliberately coded into the system, for TLA use, and what happened, is exactly what people keep warning about; it got breached, and is now a "front door," and The Powers That Be don't want that examined too closely.
klaff 4 days ago |
classified 4 days ago |
charcircuit 4 days ago |
kornork 4 days ago |
JumpCrisscross 4 days ago |
Forged-cs 4 days ago |
farceSpherule 4 days ago |
maxrev17 5 days ago |
shireboy 4 days ago |
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)